MLSGear.com notified the New Hampshire Attorney General on February 1, 2008, regarding unauthorized access to customer data between January and August 2007. Approximately 169 New Hampshire residents were affected. The breach involved SQL Injection attacks targeting a third-party service provider, exposing names, addresses, credit/debit card info, and passwords. MLSGear terminated the provider, purged passwords, and offered one year of credit monitoring via Kroll.
Affected (this filing): 169